Executive brief
A vulnerability was identified in the Linux kernel's audio subsystem (ALSA) that could allow a local user to cause system instability. The issue occurs when multiple processes attempt to access audio settings simultaneously, potentially leading to corrupted internal states or system crashes. This affects the reliability of systems running legacy audio applications.
Technical details
A data race exists in the Advanced Linux Sound Architecture (ALSA) PCM OSS emulation layer within sound/core/oss/pcm_oss.c. The 'runtime.oss.trigger' field, which is implemented as a bit field, is accessed concurrently by snd_pcm_oss_get_trigger() and snd_pcm_oss_poll() without proper synchronization. Because it is a bit field, concurrent writes can result in the corruption of adjacent bit fields, leading to undefined behavior or kernel instability. The fix introduces mutex protection using the existing 'params_lock' to ensure atomic access to the trigger state. This vulnerability was identified via fuzzing.
Affected products
- Linux Linux Kernel v6.13 and earlier
Timeline
- 2026-04-24: patched: Initial patch authored by Takashi Iwai
- 2026-05-28: disclosed: CVE published to NVD